Skip to main content
Reyhford does not only ship indicators. We publish the context SOC analysts, CISOs, and National CERTs need to interpret ICS/OT telemetry: who attacks industrial networks, which protocols are abused, how techniques map to MITRE ATT&CK for ICS, and how STIX/TAXII deliver that intelligence.

What you will learn

Threat Landscape

Why ICS/OT is under threat, who attacks, and landmark incidents.

Industrial Protocols

Modbus, S7, BACnet, IEC 104, EtherNet/IP, Guardian AST — how they work and how they are attacked.

MITRE ATT&CK for ICS

Techniques we observe most often on the sensor fleet.

TI Fundamentals

STIX 2.1, TAXII 2.1, IoCs, and confidence scoring.

Regional Intelligence

Southeast Asia focus, critical infrastructure, actor profiles.

How this connects to the product

Indicators in the TAXII 2.1 feed and Indicators API are enriched with protocol, MITRE technique, and confidence context described in these pages. Use these pages for interpretation; use the API Reference to pull the data into your SOC stack.